Codeless Cloud Starter Sites Security & Risk Analysis

wordpress.org/plugins/codeless-cloud-starter-sites

A cloud based service with 30+ templates and starter sites for Specular theme.

0 active installs v1.0.1 PHP 5.6+ WP 4.7+ Updated Dec 30, 2021
blockspatternsspecularstartertemplates
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Codeless Cloud Starter Sites Safe to Use in 2026?

Generally Safe

Score 85/100

Codeless Cloud Starter Sites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "codeless-cloud-starter-sites" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. It demonstrates excellent practices by utilizing prepared statements for all SQL queries and properly escaping all outputs. The plugin also incorporates capability checks, indicating an awareness of user permissions. Furthermore, the absence of known CVEs and any recorded historical vulnerabilities is a significant positive indicator, suggesting a commitment to security or simply a lack of discovered issues to date. The limited attack surface, with no discoverable AJAX handlers, REST API routes, shortcodes, or cron events without appropriate checks, is also commendable.

However, a notable concern arises from the complete lack of nonce checks. While capability checks are present, nonces are a critical defense-in-depth mechanism against Cross-Site Request Forgery (CSRF) attacks. Their absence leaves the plugin potentially vulnerable if any of its functionalities can be triggered by external, unauthenticated requests. The taint analysis showing zero flows with unsanitized paths is positive, but it's important to remember that taint analysis effectiveness can vary, and the lack of nonce checks is a more direct and concerning finding. In conclusion, the plugin is well-coded with strong data handling and escaping practices. The main area for improvement and potential risk lies in the implementation of nonce checks to bolster its defenses against CSRF threats.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Codeless Cloud Starter Sites Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Codeless Cloud Starter Sites Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
112 escaped
Nonce Checks
0
Capability Checks
11
File Operations
8
External Requests
5
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped112 total outputs
Attack Surface

Codeless Cloud Starter Sites Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actioninitcodeless-cloud-starter-sites.php:19
actioninitcodeless-cloud-starter-sites.php:29
filterquery_varsincludes\Admin.php:35
filtercodeless_dashboard_page_dataincludes\Admin.php:36
actionadmin_menuincludes\Admin.php:37
actionadmin_menuincludes\Admin.php:38
actionadmin_enqueue_scriptsincludes\Admin.php:39
filterwp_import_postsincludes\Importers\Helpers\Importer_Alterator.php:50
filterwp_import_postsincludes\Importers\Helpers\Importer_Alterator.php:51
filterwp_import_termsincludes\Importers\Helpers\Importer_Alterator.php:53
filterwp_insert_post_dataincludes\Importers\Helpers\Importer_Alterator.php:54
filterwp_import_nav_menu_item_argsincludes\Importers\Helpers\Importer_Alterator.php:55
filterintermediate_image_sizes_advancedincludes\Importers\Helpers\Importer_Alterator.php:56
filterimport_post_meta_keyincludes\Importers\WP\WP_Import.php:67
filterhttp_request_timeoutincludes\Importers\WP\WP_Import.php:68
actionshutdownincludes\Logger.php:72
actionrest_api_initincludes\Rest_Server.php:27
Maintenance & Trust

Codeless Cloud Starter Sites Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 30, 2021
PHP min version5.6
Downloads893

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Codeless Cloud Starter Sites Developer Profile

Codeless

7 plugins · 2K total installs

79
trust score
Avg Security Score
79/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Codeless Cloud Starter Sites

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codeless-cloud-starter-sites/assets/build/style-app.css/wp-content/plugins/codeless-cloud-starter-sites/assets/build/app.js
Script Paths
/wp-content/plugins/codeless-cloud-starter-sites/assets/build/app.js
Version Parameters
codeless-cloud-starter-sites/assets/build/style-app.css?ver=codeless-cloud-starter-sites/assets/build/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
coss-app
JS Globals
cossDash
REST Endpoints
/wp-json/codeless-starter-sites/v1/sites
FAQ

Frequently Asked Questions about Codeless Cloud Starter Sites